KDE theme wipes user's files using 'rm -rf'
Re: KDE theme wipes user's files using 'rm -rf'
The KDE store and "get hot new stuff" does have some warnings about it not being vetted, and that it does pose a risk, but...damn. Discover also updates stuff from the store once they are installed, along with system packages---use MX Updater if you want to be safer.
MXPI = MX Package Installer
QSI = Quick System Info from menu
The MX Test repository is mostly backports; not the same as Debian testing
QSI = Quick System Info from menu
The MX Test repository is mostly backports; not the same as Debian testing
Re: KDE theme wipes user's files using 'rm -rf'
It's easy to say that KDE shouldn't have let this happen but like much of Linuxdom it's probably volunteer managed or store submission devs being run on a shoestring budget... on top of that why would they be expecting to find such a heinous exploit in a theme which are almost always provided by good-hearted Users with the best of intentions in their spare time. It shouldn't have happened but KDE isn't the bad guy here the author of the exploit is... It seems like the store got on top of it very quickly, sadly, people suck... 

- uncle mark
- Posts: 851
- Joined: Sat Nov 11, 2006 9:42 pm
Re: KDE theme wipes user's files using 'rm -rf'
Yet another example of why I appreciate having become old, dull, and boring. Defaults are almost always just fine with me.
"Themes? We don't need no steenking themes."
Custom build Asus/AMD/nVidia circa 2011 -- MX 19.2 KDE
Acer Aspire 5250 -- MX 21 KDE
Toshiba Satellite C55 -- MX 18.3 Xfce
Assorted Junk -- assorted Linuxes
Acer Aspire 5250 -- MX 21 KDE
Toshiba Satellite C55 -- MX 18.3 Xfce
Assorted Junk -- assorted Linuxes
Re: KDE theme wipes user's files using 'rm -rf'
The article said every device mounted got wiped. SO if your backup or even timeshift device was mounted, it would have been wiped if they could be written to with user permissions.sunrat wrote: Wed Mar 27, 2024 5:44 pm If that happens, one should just restore the system backup they made before installing potentially damaging software!![]()
Everyone makes backups, don't they?
So better make sure you have backups that are not normally mounted or even connected to your machine. And have more than 1, in separate backup devices, as Mauser said.
I don't use Discover to update or install KDE Store customisations. First thing I do for every MX-KDE install is to remove Discover from the notifications, and install/activate Synaptic and apt-notifier.
Once in a while I visit KDE Store and check the relevant pages [eg read the reviews, ensure any updates for are for my plasma version].
Last edited by asqwerth on Wed Mar 27, 2024 11:34 pm, edited 1 time in total.
Desktop: Intel i5-4460, 16GB RAM, Intel integrated graphics
Clevo N130WU-based Ultrabook: Intel i7-8550U (Kaby Lake R), 16GB RAM, Intel integrated graphics (UEFI)
ASUS X42D laptop: AMD Phenom II, 6GB RAM, Mobility Radeon HD 5400
Clevo N130WU-based Ultrabook: Intel i7-8550U (Kaby Lake R), 16GB RAM, Intel integrated graphics (UEFI)
ASUS X42D laptop: AMD Phenom II, 6GB RAM, Mobility Radeon HD 5400
Re: KDE theme wipes user's files using 'rm -rf'
In my opinion that is the pure definition of a backup.asqwerth wrote: Wed Mar 27, 2024 10:25 pm So better make sure you have backups that are not normally mounted or even connected to your machine.
In all other cases it is merely a copy of your data.
Many might roll their eyes when they read about the 3-2-1 backup method and its modern variant 3-2-1-1-0, but it still makes sense.
And while one can argue that an offsite backup via Cloud or remote location might be a overkill for the average home user, a physically separated backup device should be the norm.
Luckily it is so easy to accomplish with MX Linux!
Re: KDE theme wipes user's files using 'rm -rf'
I wouldn't trust anything on the Cloud. The Cloud is just someone else's computer that the Stasi can get to and so can ransom-ware. My backups are on two different hard-drives inside my computer case that both have full disk encryption that I only mount them when I back up to them and then immediately dismount them bought. No Stasi is going to get the information on them, no ransom ware is going to get them, no virus can touch them, no malware will mess them up, and no nothing will get them.Dennis-TW wrote: Wed Mar 27, 2024 11:23 pmIn my opinion that is the pure definition of a backup.asqwerth wrote: Wed Mar 27, 2024 10:25 pm So better make sure you have backups that are not normally mounted or even connected to your machine.
In all other cases it is merely a copy of your data.
Many might roll their eyes when they read about the 3-2-1 backup method and its modern variant 3-2-1-1-0, but it still makes sense.
And while one can argue that an offsite backup via Cloud or remote location might be a overkill for the average home user, a physically separated backup device should be the norm.
Luckily it is so easy to accomplish with MX Linux!
I am command line illiterate.
I copy & paste to the terminal. Liars, Wiseguys, Trolls, and those without manners will be added to my ignore list. 


Re: KDE theme wipes user's files using 'rm -rf'
@uncle markuncle mark wrote: Wed Mar 27, 2024 8:02 pm
Yet another example of why I appreciate having become old, dull, and boring. Defaults are almost always just fine with me.
"Themes? We don't need no steenking themes."

You are pure "TREASURE"

Re: KDE theme wipes user's files using 'rm -rf'
fuller discussion on reddit:
https://www.reddit.com/r/kde/comments/1 ... e_out_all/
https://www.reddit.com/r/kde/comments/1 ... e_out_all/
Old RSTS hack
Registered Linux user #542196
Registered Linux user #542196
Re: KDE theme wipes user's files using 'rm -rf'
MikeR wrote: Thu Mar 28, 2024 2:32 pm fuller discussion on reddit:
https://www.reddit.com/r/kde/comments/1 ... e_out_all/
@MikeR That's a cross post from the initial post I mentioned here in post #3. viewtopic.php?p=770308#p770308
This is my Fluxbox . There are many others like it, but this one is mine. My Fluxbox is my best friend. It is my life.
I must master it as I must master my life. Without me, my Fluxbox is useless. Without my Fluxbox, I am useless.
I must master it as I must master my life. Without me, my Fluxbox is useless. Without my Fluxbox, I am useless.
Re: KDE theme wipes user's files using 'rm -rf'
KDE is a great DE, but stuff like this always reminds me why I stick with Xfce 

If it ain't broke, don't fix it.
Main: MX 23 | Second: Mint 22 | HTPC: Linux Lite 7 | VM Machine: Debian 12 | Testrig: Arch/FreeBSD 14 | Work: RHEL 8
Main: MX 23 | Second: Mint 22 | HTPC: Linux Lite 7 | VM Machine: Debian 12 | Testrig: Arch/FreeBSD 14 | Work: RHEL 8